Privacy Policy
This explains what we do with your personal data, why, and what you can ask us to do about it.
Who is responsible
Reesmen Ltd is the data controller — the company that decides why and how your data is used. We are registered in England & Wales, company number 17263287, at Unit A, 13074, 6 Greatorex Street, London E1 5NF, United Kingdom.
For anything to do with your data, email privacy@reesmen.com.
What we collect, and why
If you buy something
- Your email address. To send your order and what you bought, and so you can find the order again afterwards.
- Your order. What you bought, what it cost, when, and whether it was delivered.
- Your confirmation that you wanted immediate delivery, with the date and time. This is the record that shows why your cancellation right ended, and we would need it if a payment were ever disputed.
Our lawful basis is performance of a contract — we cannot sell you something without it — and, for keeping the records afterwards, legal obligation and legitimate interests in being able to answer a dispute.
If you create an account
- Your name, email address and, if you give one, phone number.
- A cryptographic hash of your password. We never store your actual password, and cannot recover it — which is why a reset link is the only way back in.
- Your notification preferences.
- Sign-in activity, including failed attempts, so we can lock an account somebody is trying to break into.
Automatically
Our server keeps ordinary technical logs, and we set a small number of strictly necessary cookies — see our Cookie Policy. We do not use analytics, advertising or tracking cookies, and there is nothing on this site that follows you to another one.
What we do not do
- We do not sell your data. Not to anyone, for any price.
- We do not send marketing you did not ask for. If you buy without an account, you get your order and nothing else.
- We do not store the contents of messages we send you. We record that an email was sent, to which address and when — never what was in it. That is why a licence key exists in your inbox and nowhere else on our side, and why we can re-send it but never read it back to you.
- We do not store payment card details. We never see them.
Who else processes your data
These companies process data on our behalf, under contract, and only on our instructions:
| Who | What for | Where |
|---|---|---|
| Neon | Database hosting — orders, accounts and delivery records | United Kingdom (London) |
| Resend | Sending transactional email | United States, under standard contractual clauses |
| Hostinger | Server hosting for the website itself | United Kingdom |
Where a processor is outside the UK, the transfer is covered by the standard contractual clauses and the UK addendum.
How long we keep things
- Orders and delivery records: permanently. They are our accounting records and the evidence behind any dispute, and UK law requires company records to be kept for six years. We do not delete or edit an order once it is placed.
- Account details: until you close the account. After that we keep only what is attached to your orders.
- Sign-in and security records: 12 months.
Your rights
You can ask us to:
- Give you a copy of the data we hold about you.
- Correct anything that is wrong.
- Delete your account and personal details. We will, but we cannot delete an order — it is an accounting record, and keeping it is a legal obligation rather than a choice.
- Stop sending you anything that is not about an order.
- Give you your data in a portable format.
Email privacy@reesmen.com and we will respond within one month.
If you are unhappy with how we have handled your data you can complain to the Information Commissioner’s Office at ico.org.uk, though we would rather you told us first so we can put it right.
Keeping it safe
Everything travels over an encrypted connection. Passwords are stored as one-way hashes and session tokens only as digests, so a stolen copy of our database would yield neither. Licence keys are encrypted at rest with a key held separately from the database, so the same is true of your purchases. Access to customer data is limited to the people who need it, and every time somebody reads a licence key it is recorded.
Children
This service is not intended for anyone under 16, and we do not knowingly collect their data.
Changes
If we change this policy we will update the date at the bottom of this page, and tell account holders if the change is significant.